CVE 5.3 MEDIUM

Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation_CVE-2026-3143

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update.

Basic Information

ID CVE-2026-3143
Source Wordfence
Published May 1, 2026 at 13:28

Affected Product

Vendor boldgrid
Product Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
Affected Versions boldgrid Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.